CVE-2023-52977

EUVD-2023-59743
In the Linux kernel, the following vulnerability has been resolved:

net: openvswitch: fix flow memory leak in ovs_flow_cmd_new

Syzkaller reports a memory leak of new_flow in ovs_flow_cmd_new() as it is
not freed when an allocation of a key fails.

BUG: memory leak
unreferenced object 0xffff888116668000 (size 632):
  comm "syz-executor231", pid 1090, jiffies 4294844701 (age 18.871s)
  hex dump (first 32 bytes):
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace:
    [<00000000defa3494>] kmem_cache_zalloc include/linux/slab.h:654 [inline]
    [<00000000defa3494>] ovs_flow_alloc+0x19/0x180 net/openvswitch/flow_table.c:77
    [<00000000c67d8873>] ovs_flow_cmd_new+0x1de/0xd40 net/openvswitch/datapath.c:957
    [<0000000010a539a8>] genl_family_rcv_msg_doit+0x22d/0x330 net/netlink/genetlink.c:739
    [<00000000dff3302d>] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline]
    [<00000000dff3302d>] genl_rcv_msg+0x328/0x590 net/netlink/genetlink.c:800
    [<000000000286dd87>] netlink_rcv_skb+0x153/0x430 net/netlink/af_netlink.c:2515
    [<0000000061fed410>] genl_rcv+0x24/0x40 net/netlink/genetlink.c:811
    [<000000009dc0f111>] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]
    [<000000009dc0f111>] netlink_unicast+0x545/0x7f0 net/netlink/af_netlink.c:1339
    [<000000004a5ee816>] netlink_sendmsg+0x8e7/0xde0 net/netlink/af_netlink.c:1934
    [<00000000482b476f>] sock_sendmsg_nosec net/socket.c:651 [inline]
    [<00000000482b476f>] sock_sendmsg+0x152/0x190 net/socket.c:671
    [<00000000698574ba>] ____sys_sendmsg+0x70a/0x870 net/socket.c:2356
    [<00000000d28d9e11>] ___sys_sendmsg+0xf3/0x170 net/socket.c:2410
    [<0000000083ba9120>] __sys_sendmsg+0xe5/0x1b0 net/socket.c:2439
    [<00000000c00628f8>] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46
    [<000000004abfdcf4>] entry_SYSCALL_64_after_hwframe+0x61/0xc6

To fix this the patch rearranges the goto labels to reflect the order of
object allocations and adds appropriate goto statements on the error
paths.

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
4.9.337 ≤
𝑥
< 4.10
linuxlinux_kernel
4.14.303 ≤
𝑥
< 4.14.306
linuxlinux_kernel
4.19.270 ≤
𝑥
< 4.19.273
linuxlinux_kernel
5.4.229 ≤
𝑥
< 5.4.232
linuxlinux_kernel
5.10.163 ≤
𝑥
< 5.10.168
linuxlinux_kernel
5.15.86 ≤
𝑥
< 5.15.93
linuxlinux_kernel
6.0.16 ≤
𝑥
< 6.1
linuxlinux_kernel
6.1.2 ≤
𝑥
< 6.1.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.129-1
fixed
bookworm (security)
6.1.128-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.234-1
fixed
sid
6.12.20-1
fixed
trixie
6.12.19-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
trusty
needs-triage
xenial
needs-triage
linux-allwinner-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
trusty
needs-triage
xenial
needs-triage
linux-aws-5.0
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-aws-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-aws-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-aws-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-aws-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-aws-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-aws-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-aws-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-aws-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
linux-aws-hwe
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
needs-triage
linux-azure
bionic
ignored
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
trusty
needs-triage
xenial
needs-triage
linux-azure-4.15
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-azure-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-azure-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-azure-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-azure-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-azure-edge
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-fde
focal
ignored
jammy
needs-triage
noble
dne
oracular
dne
linux-azure-fde-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-azure-fde-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-fde-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
linux-bluefield
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
xenial
needs-triage
linux-gcp
bionic
ignored
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
xenial
needs-triage
linux-gcp-4.15
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-gcp-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gcp-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-gcp-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-gcp-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-gcp-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
linux-gke
focal
ignored
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-gke-4.15
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gke-5.15
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gke-5.4
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gkeop
focal
ignored
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-gkeop-5.15
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gkeop-5.4
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-hwe
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
needs-triage
linux-hwe-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-hwe-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-hwe-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-hwe-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-hwe-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-hwe-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-hwe-edge
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
ignored
linux-ibm
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-ibm-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-ibm-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-intel-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-intel-iot-realtime
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-intel-iotg
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-intel-iotg-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-iot
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-kvm
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
xenial
needs-triage
linux-lowlatency
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
linux-lowlatency-hwe-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-lowlatency-hwe-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-lowlatency-hwe-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-lowlatency-hwe-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-lowlatency-hwe-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-lowlatency-hwe-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-lts-xenial
focal
dne
jammy
dne
noble
dne
oracular
dne
trusty
needs-triage
linux-nvidia
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-nvidia-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-nvidia-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-nvidia-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-nvidia-lowlatency
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-nvidia-tegra
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-nvidia-tegra-igx
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-oem
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oem-5.10
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-5.14
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-5.17
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-5.6
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-6.0
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-6.1
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-oem-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-6.8
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-oracle
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
xenial
needs-triage
linux-oracle-5.0
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oracle-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oracle-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-raspi
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
linux-raspi-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-raspi-realtime
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-raspi2
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-realtime
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
linux-riscv
focal
ignored
jammy
ignored
noble
needs-triage
oracular
needs-triage
linux-riscv-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-riscv-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-riscv-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-riscv-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-riscv-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-riscv-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-starfive-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-starfive-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-starfive-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-xilinx-zynqmp
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne